SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis practical assignment is a research paper on how to use the ARP protocol to monitor local area networks. The ARP protocol can be used to take an inventory of computers on the network, alert when new machines are connected, inspect ARP traffic for computers that are scanning the network, and if you record the ARP traffic, it can provide a tool to help clean up after worm attacks and provide a record of communications to explain other events. The practical begins with a description of the ARP protocol, packet formats, and characteristics of the protocol. The next section contains a survey of different ARP monitoring programs that are available such as arpwatch7 and tcpdump. The last section talks about monitoring wireless networks. The same principles for monitoring wired networks apply to wireless if you can get windump to show ARP traffic on your wireless computer. These tools by no means provide comprehensive network security. It would be possible to conceal a computer from the ARP monitoring by not broadcasting ARP packets.